โ† All Excel VBA Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real Excel VBA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. A VBA workbook is part of a system undergoing FedRAMP authorization. Which security control directly applies to the workbook's data handling?

    Answer: Ensuring data at rest is encrypted and access is limited to users with the appropriate FedRAMP-defined clearance level

    FedRAMP requires federal cloud services to meet NIST 800-53 controls including data encryption at rest and strict access controls aligned with authorization levels.

  2. Under OSHA recordkeeping regulations (29 CFR 1904), a VBA tool tracks workplace incidents. Which validation rule is compliance-critical?

    Answer: Enforcing that incident records are entered within 7 days of occurrence and cannot be modified after supervisor sign-off

    OSHA requires workplace injuries and illnesses to be recorded accurately and within specified timeframes; VBA validation prevents late entry and unauthorized modification.

  3. A VBA solution supports COSO Internal Control framework documentation. Which feature best supports the Control Activities component?

    Answer: Implementing segregation of duties by restricting data entry, review, and approval actions to separate user roles enforced in VBA

    COSO's Control Activities component includes segregation of duties; VBA user-role enforcement ensures that no single person can initiate, record, and approve the same transaction.

  4. A compliance analyst needs a VBA macro to support GDPR Article 30 Record of Processing Activities (RoPA). What should the macro maintain?

    Answer: A structured log recording the purpose, legal basis, data categories, retention period, and recipients for each data processing activity

    GDPR Article 30 requires controllers to maintain detailed records of processing activities including purposes, legal bases, data categories, and retention schedules.

  5. Which VBA practice aligns with the SEC's Rule 17a-4 requirement for electronic record preservation?

    Answer: Writing finalized trade records to a WORM (Write Once Read Many) compliant output and preventing any VBA routine from modifying archived data

    SEC Rule 17a-4 requires broker-dealers to preserve electronic records in a non-rewritable, non-erasable format; VBA must enforce read-only status on archived records.

  6. A VBA workbook is used in a SOX-audited environment. An auditor asks for evidence of IT General Controls (ITGCs) over the spreadsheet. Which VBA artifact best provides this evidence?

    Answer: A VBA-generated change log showing every modification to formulas or data, including user, timestamp, before-value, and after-value

    ITGCs require evidence of controls over financial applications; a detailed VBA change log with user attribution and before/after values directly supports ITGC documentation for auditors.

  7. A VBA macro is used to generate reports for a company subject to the Consumer Financial Protection Bureau (CFPB) fair lending rules. Which anti-discrimination control should be built in?

    Answer: Flagging any loan pricing or decisioning output where similarly qualified applicants in protected classes received materially different outcomes for human review

    CFPB fair lending rules require lenders to identify and remediate disparate impact; VBA logic that flags differential outcomes for protected class members supports compliance monitoring.